Antivirus

Avast security tools hijacked in order to crack antivirus protection

Researchers spot new campaign that can turn off antivirus protection Malware uses legitimate Avast Anti-Rootkit driver to access kernel level Once antivirus is deactivated, the malware can proceed without detection Hackers are using a legitimate Avast Anti-Rootkit driver to disguise their malware, turn off antivirus protection, and infect systems, experts have warned. The vulnerable driver


  • Researchers spot new campaign that can turn off antivirus protection
  • Malware uses legitimate Avast Anti-Rootkit driver to access kernel level
  • Once antivirus is deactivated, the malware can proceed without detection

Hackers are using a legitimate Avast Anti-Rootkit driver to disguise their malware, turn off antivirus protection, and infect systems, experts have warned.

The vulnerable driver has been exploited in a number of attacks since 2021, with the original vulnerabilities being present since at least 2016, research by Trellix, has claimed, noting the malware can use the vulnerable driver to end the processes of security software at the kernel level.

The malware in question belongs to the AV Killer family, with the attack using a vector known as bring-your-own-vulnerable-driver (BYOVD) to infect the system.

Virus can turn off antivirus

Trellix outlined how the malware uses a file named ‘kill-floor.exe’ to place the vulnerable driver named ‘ntfs.bin’ into the default Windows user folder, before using the Service Control executable (sc.exe) to register the driver using the ‘aswArPot.sys’ service.

Included within the malware is a hardcoded list of 142 processes used by common security products, which is used to check system process snapshots for any matches.

The malware then uses the ‘DeviceIoControl’ API to run the relevant commands to end the process, thereby preventing the antivirus from detecting the malware.

The hardcoded list includes processes belonging to a number of security products from names such as McAfee, Avast, Microsoft Defender, BlackBerry, Sophos, and many more.

As BleepingComputer points out, this isn’t the first time a BYOVD attack has exploited a vulnerable Avast driver, with the 2021 Avoslocker ransomware attacks abusing an Avast Anti-R

Read More

Be the first to write a comment.

Leave a Reply

Your email address will not be published. Required fields are marked *

Antivirus

Why There’s Simply No Need For Android Antivirus Apps Anymore

Many Android users install an antivirus app on a new device without thinking twice. In 2026, there are good reasons to skip that step entirely…

Many Android users install an antivirus app on a new device without thinking twice. In 2026, there are good reasons to skip that step entirely…
Read More

Continue Reading
Antivirus

‘People use smartphones more but invest less in their security’: New report claims McAfee and Norton remain the most loved antivirus brands as users ditch lesser-known security products for free tools like Microsoft Defender or Apple Xprotect

Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Most smartphone users rely on built-in security without additional protection Paid antivirus adoption on mobile devices continues to decline steadily A significant share


  • Most smartphone users rely on built-in security without additional protection
  • Paid antivirus adoption on mobile devices continues to decline steadily
  • A significant share of users remains unprotected or unaware of safeguards

Most Americans now use their smartphones more than their computers, but very few spend money to protect those phones from hackers, new research has claimed.

A Cybernews report surveyed over 1,000 American adults, and found only 18% of mobile phone users pay for third-party antivirus software.

Built-in tools like Microsoft Defender and Apple’s XProtect have become the default choice for most people, while McAfee and Norton lead the paid market for the second year in a row.

Latest Videos From

You may like

  • Best antivirus software Best Antivirus Software 2026
  • People using Windows 11 laptops Can Windows 11’s built-in antivirus keep you safe? Microsoft thinks so
  • Norton 36src Premium Norton 360 Premium will protect your devices from AI scams, malware, and identity theft for less than $30

Smartphone owners are skipping extra security protections

Most consumers believe the security features already built into their phones are sufficient for daily use, and see little reason to spend extra money on something they think they already own for free.

Roughly 14% of mobile users say they have no cybersecurity tools installed at all on their devices. Another 16% cannot even name what protections they currently have in place.

On desktop computers, the situation looks very different, with far fewer unprotected machines and much wider adoption of third-party security tools.

Windows Defender and Apple’s native security features now serve as the primary defense for 53% of computer users and 51% of mobile users.

Most people choose these free options because they trust the operating system vendor to provide adequate baseline protection.

Paid antivirus adoption on computers has actually grown by 2% since last year, reaching 41% of users.

On mobile devices, however, third-party antivirus usage has dropped by roughly 10% over the same period, falling from 28% to just 18%.

What to read next

  • Customer at home looking happy because his network is protected by ESET Home Security We all need digital protection and the ESET Home Security Plan is the bees knees
  • A hand holding a mobile phone scans a QR code on a blurry laptop screen. The phone issues a warning that the QR code could be malicious. Microsoft phishing threat report shows 146% surge in quishing
  • Malware attack virus alert , malicious software infection , cyber security awareness training to protect business Time for an upgrade? Report warns outdated operating systems could be the ‘unnecessary risk’ your business forgot about

Mobile users face growing risks

Ransomware attacks targeting smartphones are still less common than those aimed at computers, but the threat landscape is shifting rapidly.

Users who depend solely on the free security tools that came with their phones may be underestimating what modern cybercriminals can do.

Paid subscriptions have gained ground over free alternatives, yet the majority of mobile owners still avoid spending money on dedicated protection.

Cybercrime exposure does influence some users to change their habits, but personal experience is not the main driver of adoption for most people.

Many users employ layered security approach, combining antivirus with VPNs and password managers.

However, the data shows that a large segment of mobile users remain either unprotected or unsure about what safeguards they have.

Established brands like McAfee and Norton continue to benefit from user trust, while lesser-known products struggle to gain acceptance even when their features are comparable.


Google logo on a black background next to text reading

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

Read More

Continue Reading
Antivirus

Surfshark One review: Adequate antivirus protection with caveats

At a glanceExpert’s Rating Pros Clean, extremely simple interface Alternative ID lets you mask your whole identity, not just an email address VPN service is solid Cons Full scans hit PC performance hard Very few settings to adjust Not as many features as similarly priced rivals Our Verdict If VPN coverage is your first priority…

At a glanceExpert’s Rating

Pros

Clean, extremely simple interface

Alternative ID lets you mask your whole identity, not just an email address

VPN service is solid

Cons

Full scans hit PC performance hard

Very few settings to adjust

Not as many features as similarly priced rivals

Our Verdict
If VPN coverage is your first priority…
Read More

Continue Reading
Antivirus

NITDA raises alarm on DeepLoad AI malware attacks, proffers solutions

“Never paste commands from a website into your computer; legitimate software never asks for this. Do not open files named ‘Chrome Setup’ or ‘Firefox Installer’ from USB drives; scan all USB devices with antivirus software before use,” the agency said, warning corporate companies of possible cyber attacks…

“Never paste commands from a website into your computer; legitimate software never asks for this. Do not open files named ‘Chrome Setup’ or ‘Firefox Installer’ from USB drives; scan all USB devices with antivirus software before use,” the agency said, warning corporate companies of possible cyber attacks…
Read More

Continue Reading